← Back to browse · API

CVE-2024-0916

Severity
CRITICAL
CVSS
10.0
EPSS
0.00999
Risk score
40.35
CISA KEV
No
PoC
No
Published
2024-04-25
Modified
2024-08-06
First seen
2026-08-07
Aliases
EUVD-2024-16698, GHSA-RVPG-MQJJ-6HQP
Products
Webkul Software:UvDesk Community, Webkul Software:UvDesk Community 1.0.0 ≤1.1.3
Sources
euvd EUVD-2024-16698

Description

Unauthenticated file upload allows remote code execution. This issue affects UvDesk Community: from 1.0.0 through 1.1.3.

References